When you first sign in without an organisation, Threat Detective takes you to a single setup screen: "Let's analyse your first piece of software."
Create your organisation
Enter your Organisation name: your company or team name. You can add more projects later.
You'll also need to tick the authorisation checkbox confirming you're authorised to accept the Service Agreement and Data Processing Agreement on behalf of your organisation. Both documents are linked from the form. The person who creates the organisation becomes its owner.
Choose how to start
The setup screen gives you three paths:
Upload & analyse: drop a CycloneDX or SPDX JSON file (up to 10 MB on this screen) and we'll create your organisation, a first project and the software item from the SBOM's own metadata, then start the import straight away.
Try a sample SBOM: creates a demo organisation with a project called Sample Insulin Pump Controller, imported through the normal pipeline. The findings, triage queue and reports are all real, so it's a safe way to explore the full workflow. The sample doesn't count against your plan's project limit.
Set up an empty project: no SBOM yet? Create the organisation and project only, and add software manually afterwards.
Add device details to your project
Projects group the SBOMs and versions for a single medical device. From the project's Settings tab you can record:
Device trade name: the device name as it appears in your submission, printed on the cover of every generated report.
Model: for example, VS-2100.
Submission reference: optional, once assigned (for example, K250123).
Filling these in early means every report you export is already labelled for your submission.
Already have an organisation?
Create further projects from the organisation Overview page with New project. The Explore a sample device button sits alongside it if you'd like a sandbox at any point.
